Category

How to Secure Your Account with Two-Factor Authentication in BoldDesk

Updated:

Two-Factor Authentication (2FA) adds an extra layer of security to BoldDesk accounts by requiring a time-based one-time passcode (TOTP) in addition to a password. This feature helps protect sensitive ticket data and prevents unauthorized access.

  • Supported for:
    • Agents: Enable individually or enforce organization-wide via Agent Portal settings.
    • Contacts (Customers): Enable individually or enforce globally via Agent Portal settings.
  • Applies to: BoldDesk form logins only. Social or custom SSO logins bypass 2FA.

Prerequisites

  • User must sign in using BoldDesk form login.
  • A TOTP authenticator app (for example, Google Authenticator, Microsoft Authenticator) installed on the user’s mobile device.



Please watch this video tutorial for further information.

2FA for Agents

Agents manage sensitive tickets and administrative settings. Enabling 2FA ensures secure access to the BoldDesk Agent Portal.

Enabling 2FA for Individual Agents

  1. Log in to your BoldDesk account.

  2. Navigate to your Personal Settings.

  3. Click the Security tab.

  4. Click Enable.

    Enable 2FA.png

Once enabled, you will be required to provide a second form of identification, such as a code generated by an authenticator app like Google Authenticator or Microsoft Authenticator, each time you log in.

Enforcing 2FA for All Agents (Admin Only)

As an admin, you can enforce 2FA for all agents to ensure the security of all accounts. Here’s how:

  1. Log in to your BoldDesk account as an admin.
  2. Navigate to Admin Settings.
  3. Click the Agent Portal option.
  4. Go to the Login tab.
  5. Select the Enforce two-factor authentication (2FA) for all agents option.

Once this setting is enabled, all agents will be required to set up and use 2FA each time they log in.

Enforce 2FA.png

Disabling 2FA for Specific Agent

An option to disable 2FA for a specific agent is now available. Once disabled, the agent’s configured 2FA device will be removed.

Disable Two Factor Authentication for Users.gif

  • 2FA feature is only supported for BoldDesk form logins. It is not applicable for social or custom SSO logins.
  • Two-Factor Authentication (2FA) for customers is enabled by default. However, to activate this feature, a customer must enable it within their profile settings.
  • BoldDesk does not support configuring or enforcing Two-Factor Authentication (2FA) at the brand level for the Agent Portal. Any 2FA settings apply globally and cannot be restricted to agents associated with a specific brand. Additionally, there is no available workaround to enable brand-specific 2FA enforcement at this time.

2FA for Contacts (Customers)

Contacts use the BoldDesk Customer Portal to view and manage tickets, which may include personal or regulated information. Enabling 2FA for contacts strengthens account security and helps prevent unauthorized access to sensitive data.

How to Enable 2FA in Customer Portal

  • Sign in to the BoldDesk Customer Portal.

  • Navigate to My ProfileSecurity.

  • Click Enable under Two-Factor Authentication.

    Enabling 2FA.png

  • Scan the QR code with your authenticator app.

  • Enter the 6-digit verification code and click Verify.

  • Save recovery codes securely.

Disable Two‑Factor Authentication (2FA) for a Specific Contact

This section explains how to disable Two‑Factor Authentication (2FA) for an individual contact in BoldDesk. Disabling 2FA may be required when a contact is unable to complete authentication or needs to reset their security settings. The action can be performed directly from the Contacts module in the Agent Portal.

Navigation path:

  • Sign in to the BoldDesk Agent Portal.

  • Navigate to Contacts.

  • Locate the required contact.

  • Click the More (⋮) option for the selected contact.

  • Select Disable 2FA.

    Disable 2FA.png

Admin Assistance for Contacts

Admins now have two options for managing contact 2FA:

1. Enforce 2FA for All Contacts
To require every contact to set up 2FA:

  • Navigate to AdminCustomer Portal SettingsSecurity tab.
  • Under Two-Factor Authentication (2FA), enable the option:
    • Enforce two-factor authentication (2FA) for all users.”
  • Save the changes.

2. Assist Individual Contacts

  • Resend recovery codes to help the contact regain access.

    Recovery codes.png

  • When 2FA is enforced for all contacts, BoldDesk does not allow disabling 2FA for an individual contact if they lose access to their authenticator app.
    Instead, administrators can resend recovery codes to help the contact regain access and reconfigure 2FA.
  • If a customer has lost their 2FA authentication, you may resend the recovery code to them. After logging into the portal with this code, the customer can re-activate 2FA within their profile.

Frequently Asked Questions

  1. Does BoldDesk Two-Factor Authentication (2FA) work with SSO?
    No. Two-Factor Authentication (2FA) applies only to BoldDesk form logins. Social login and custom SSO login bypass 2FA.

  2. Can an agent choose any authenticator app for TOTP codes?
    Yes. Agents can use any compatible TOTP authenticator app, such as Google Authenticator or Microsoft Authenticator.

  3. Is Two-Factor Authentication (2FA) mandatory for all agents?
    Two-Factor Authentication (2FA) is mandatory for all agents only when an administrator enables Enforce two-factor authentication (2FA) for all agents in Admin Settings → Agent Portal → Login.

  4. Can contacts (customers) use Two-Factor Authentication (2FA)?
    Yes. Contacts can enable Two-Factor Authentication (2FA) in the Customer Portal under My Profile → Security, unless Two-Factor Authentication (2FA) is already enforced for all contacts by an administrator.

  5. What should an admin do if a contact loses access to the authenticator app?
    An administrator can resend recovery codes so the contact can sign in and reconfigure Two-Factor Authentication (2FA).

  6. If contact 2FA enforcement is disabled, will contacts stop seeing 2FA prompts?
    No. Disabling enforcement only removes the requirement that contacts must set up 2FA. Contacts who already enabled Two-Factor Authentication (2FA) in My Profile → Security will continue to receive 2FA prompts during form login.

  7. Can an admin disable Two-Factor Authentication (2FA) for an individual contact when contact 2FA is enforced?
    No. When Enforce two-factor authentication (2FA) for all users is enabled for contacts, BoldDesk does not allow disabling Two-Factor Authentication (2FA) for a single contact. The supported admin action is to resend recovery codes.

  8. What happens when Two-Factor Authentication (2FA) is disabled for an agent?
    Disabling Two-Factor Authentication (2FA) removes the agent’s configured 2FA device from the agent account. The agent will not be prompted for a TOTP code on future form logins unless 2FA is enabled again (or global enforcement requires setup again).

Related Articles

  1. How to Set Up Single Sign-On (SSO) in BoldDesk
  2. How to Configure Customer Portal Login to Bypass the Sign‑In Page
Was this article useful?
Like
Dislike
Help us improve this page
Please provide feedback or comments
Comments (0)
Access denied
Access denied
Access denied
Access denied

No articles or sections found
No articles or sections found